All bodies  ›  Legislative Analyst's Office  ›  Nonreporting Entities' Information Security Compliance

LAO

Nonreporting Entities' Information Security Compliance

Legislative Analyst's Office · lao-4756 · Report · 2023-03-30

Read the report at Legislative Analyst's Office ↗

2023-24 BUDGET Nonreporting Entities’ Information Security Compliance GABRIEL PETEK | LEGISLATIVE ANALYST MARCH 2023 www.lao.ca.gov 1 AN LAO REPORT 2 LEGISLATIVE ANALYST’S OFFICE AN LAO REPORT Executive Summary Report Satisfies Supplemental Report Requirement. The Legislature adopted supplemental report language (SRL) in 2022 directing our office to publish a report on nonreporting entities’ information security (IS) compliance. (A nonreporting entity is a state entity that is not under the direct authority of the Governor and, therefore, generally is considered to be outside of the California Department of Technology’s [CDT’s] IS authority.) Specifically, the SRL required the report to identify each of the nonreporting entities, consider whether some of them could benefit from compliance with and reporting on IS policies and procedures similar to those set by CDT, and provide options for the Legislature to consider to improve nonreporting entities’ IS compliance and achieve a certain IS maturity level (that is, how prepared state entities’ IS programs are to prevent and/or respond to a cyberattack and/or threat). The publication of this report satisfies the requirements of the SRL. Report Identifies 22 Nonreporting Entities Based on One Statutory Interpretation. Our office, in consultation with CDT, created a list of nonreporting entities based on one possible interpretation of state statute. We identified these entities based on specific definitions in statute, along with reviews of constitutional and statutory authorities for these entities. However, this list is not definitive or exhaustive as other statutory interpretations, such as a different interpretation of a state entity’s reporting relationship with the Governor, could add or remove an entity from the nonreporting entities list. These alternative statutory interpretations highlight a problematic ambiguity in state IS authority. Therefore, we recommend the Legislature amend statute to clearly identify which entities are nonreporting for the purposes of IS. Chapter 773 of 2022 (AB 2135, Irwin) Addresses Some Compliance and Governance Issues Considered in SRL Report. Assembly Bill 2135 requires nonreporting entities to perform IS compliance and reporting activities similar to those required of reporting entities. These include using certain federal authorities for their policies, procedures, and standards; certifying compliance with IS requirements annually; and undergoing biennial independent security assessments. While some of the benefits and improvements in nonreporting entities’ IS compliance will depend on AB 2135 implementation, we consider some of the compliance and governance issues in the SRL to be addressed to a significant extent by AB 2135. The remainder of our report focuses on the results of our research on nonreporting entities’ IS programs across the three topics of IS governance, IS compliance, and IS/information technology infrastructure and staffing. Evaluation of Nonreporting Entities’ IS Programs Presents Options to Improve Their Compliance and Maturity. The two figures below summarize (1) the findings of our analysis and (2) options for legislative action based on those findings. Our analysis included interviewing 34 entities (including 17 of 22 nonreporting entities); meeting with entities in the state’s IS governance structure; reviewing federal and state IS policies, procedures, and standards; and assessing nonreporting entity IS documentation. www.lao.ca.gov 3 AN LAO REPORT Summary of Findings on Nonreporting Entities’ IS Programs Topic Findings IS Governance Significant differences in nonreporting entity functions, roles, and size. Majority of nonreporting entities cited state IS policies, procedures, and standards as primary framework for IS programs. Many nonreporting entities receive and use threat intelligence information from Cal-CSIC, but only some sought Cal-CSIC and CDT’s guidance on Cal-Secure implementation. Many nonreporting entities found CDT’s IS resources difficult to use. Some entities said statutory ambiguity impacted IS program decision-making. IS Compliance Nearly all nonreporting entities underwent an ISA in the past several years. Some nonreporting entities voluntarily comply with state IS policies, procedures, and standards. Some nonreporting entities in voluntary compliance cited a lack of documentation review by CDT. Some nonreporting entities required to perform additional IS compliance activities by cyber insurance providers. Some nonreporting entities identified the lack of certification and education opportunities for existing staff to improve compliance. IS/IT Infrastructure Several nonreporting entities use CDT IS and IT service offerings, but some nonreporting entities said private and Staffing vendors offered better levels of service and pricing for IS and IT services. Nearly all nonreporting entities cited significant challenges hiring, training, and retaining IS staff. Smaller nonreporting entities raised concerns about procurement delays. Summary of Options to Improve Nonreporting Entities’ IS Compliance and Maturity Topic Options IS Governance Consider amending CDT’s IS authority to address statutory ambiguity of state agency and state entity definitions and use. Recommend monitoring nonreporting entities’ compliance with and implementation of AB 2135.a Consider directing CDT to improve ease of use of IS-related guidance, information, and templates. Consider directing Cal-CSIC to increase outreach to nonreporting entities implementing Cal-Secure. IS Compliance Consider opportunities to condition state funding on compliance with federal and state IS policies, procedures, and standards. Consider directing Cal-CSIC and CDT to report to the Legislature on Cal-Secure implementation. Consider requiring CDT to develop centralized IS training hub for IS compliance certification and education. Consider requiring an evaluation of major cyber insurance products to understand compliance requirements. IS/IT Infrastructure Consider expanding use of shared service contracts for IS services. and Staffing Consider directing administration to expand on existing recruitment, training, and retention efforts to increase size of IS workforce. Consider monitoring State Data Center rate reassessment process for IT services. Consider mandating certain network traffic be directed to CDT’s SOC for monitoring. Consider directing administration to evaluate division of IT procurement responsibilities. a Chapter 773 of 2022 (AB 2135, Irwin). IS = information security; Cal-CSIC = California Cybersecurity Integration Center; CDT = California Department of Technology; ISA = independent security assessment; IT = information technology; and SOC = Security Operations Center. 4 LEGISLATIVE ANALYST’S OFFICE AN LAO REPORT INTRODUCTION Report Satisfies Supplemental Report The publication of this report satisfies the Requirement. The Legislature adopted requirements of the SRL. supplemental report language (SRL) in 2022 Report Maintains Confidentiality of directing our office to publish a report on Information as Required by State Law. nonreporting entities’ information security (IS) The SRL also required our office to maintain the compliance. (We define nonreporting entities and confidentiality of the information collected from provide more information on IS compliance in nonreporting entities in compliance with state law. the “Background” section.) Specifically, the SRL For example, Government Code Section 7929.210 required the report to, at a minimum, identify each limits disclosure of state IS documents if their of the nonreporting entities, consider whether some disclosure “would reveal vulnerabilities to, or of them could benefit from compliance with and otherwise increase the potential for an attack reporting on IS policies and procedures similar to on,” state information technology (IT) systems. those set by the California Department of Technology In addition, Government Code Section 8592.45 (CDT), and provide options for the Legislature prohibits disclosure of state IS information on to consider to improve nonreporting entities’ IS critical infrastructure IT systems. This report compliance to be comparable with reporting complies with state law and the SRL requirement, entities and achieve a certain IS maturity level. as well as legal and policy guidance from CDT on publication of the list of nonreporting entities. BACKGROUND In this section, we provide definitions for terms we definitions of state agency and state entity within use throughout the report, specifically nonreporting CDT’s IS authority list specific agencies and types and reporting entities, and relevant background of entities subject to their authority that is narrower information across three different topics—IS than the preceding definition of state agency. In the governance, IS compliance, and IS/IT infrastructure “Major Authorities” appendix on pages 21-23 of the and staffing. report, we provide more information about these Definitions of Nonreporting and Reporting statutory definitions as well as other IS-related Entities. A nonreporting entity is a state entity that authorities that are relevant to this report. is not under the direct authority of the Governor and, IS Governance therefore, generally is considered to be outside of CDT’s IS authority. In contrast, a reporting entity is Definition of IS Governance. In this report, we define IS governance as the structure that under the direct authority of the Governor, is subject is responsible for the coordination of statewide to CDT’s IS authority and, therefore, is directed cybersecurity strategy and development of state IS by CDT to manage risk and security according policies, procedures, and standards. Key entities in to its policies, procedures, and standards. the state’s IS governance structure that are relevant The distinction between entities based on their to this report include the California Cybersecurity reporting relationship with the Governor comes from Integration Center (Cal-CSIC) and CDT’s Office of interpretations of different statutory definitions in Information Security (OIS). We acknowledge that CDT’s IS authority—that is, the definition of “state there are other entities, such as federal entities and agency” (Government Code Sections 11000 and industry organizations, involved in IS governance. 11546.1[e][1]) and “state entity” (Government Code While the focus of our IS governance section is on Section 11546.1[e][2]). Whereas one definition of the state’s IS governance structure, we will discuss state agency applies to all executive branch entities, other entities’ roles in IS governance as needed in including nonreporting entities, the two other the report. www.lao.ca.gov 5 AN LAO REPORT Cal-CSIC Provides Statewide IS Leadership. Special Publication (SP) 800-53 as their sources for Cal-CSIC is the lead entity for coordinating the state’s policies, procedures, and standards. More statewide IS activities; gathering and disseminating information about the IS sections of SAM and SIMM, threat intelligence to state entities from the federal FIPS, and NIST SP 800-53 is provided in the “Major government, county and other local governments, Authorities” appendix on pages 21-23 of the report. and private companies; and responding to Cal-CSIC and OIS Work Together on cybersecurity incidents. Cal-CSIC is a partnership Implementation of State’s Multiyear IS Roadmap. of four state entities: the California Governor’s OIS, in collaboration with other Cal-CSIC partners, Office of Emergency Services, which administers published the state’s first five-year IS roadmap— Cal-CSIC; CDT; the California Highway Patrol; and referred to as Cal-Secure—in October 2021. The the California Military Department (CMD). Figure 1 administration’s intent is for the roadmap to prioritize provides a graphical representation of Cal-CSIC and reporting entities’ cybersecurity initiatives and its partners. technical capability investments over the next five OIS Sets Policies, Procedures, and Standards years. Nonreporting entities also can voluntarily for Reporting Entities. OIS is responsible for the opt into Cal-Secure implementation. State entities creation of IS policies, procedures, and standards have begun requesting additional funding and/or that reporting entities must follow. OIS formalizes positions to acquire capabilities and lead initiatives IS policies, procedures, and standards in the (as identified by the roadmap). Our understanding State Administrative Manual (SAM) and Statewide is that there are no reporting requirements specific Information Management Manual (SIMM). Nearly to Cal-Secure; rather, reporting entities will report all of the IS sections in SAM and SIMM use Federal to CDT OIS on Cal-Secure progress as part of their Information Processing Standards (FIPS) and/or routine reporting requirements, and nonreporting National Institute of Standards and Technology (NIST) entities will not report their progress. More information about Cal-Secure is provided in the “Major Authorities” Figure 1 appendix on pages 21-23 of the report. Cal-CSIC Coordinates Statewide IS Activities Nonreporting Entities’ IS Governance Varies. Historically, Education Local Segments Governments nonreporting entities generally have not been subject to the state’s IS governance structure. CalOES There have been exceptions, however. For example, nonreporting entities are required to submit Other Executive technology recovery plans for Branch SOCs CDT Cal-CSIC CHP critical infrastructure controls and OIS information to CDT pursuant to SOC Government Code Section 8592.35. State Entity Also, pursuant to Government Code IS Programs & Staff CMD Section 8586.5, some nonreporting CND entities are represented within County Private Cal-CSIC such as the Department Governments Companies of Justice. In addition, a number of nonreporting entities are governed Cal-CSIC = California Cybersecurity Integration Center; IS = information security; CalOES = California Governor's Office of Emergency Services; CHP = California Highway Patrol; CMD = California Military Department; CND = Cyber by other federal entities and industry Network Defense Team; CDT = California Department of Technology; OIS = Office of Information Security; and SOC = Security Operations Center. organizations and, therefore, are subject to their specific IS policies, procedures, and standards. 6 LEGISLATIVE ANALYST’S OFFICE AN LAO REPORT Recently Enacted Legislation Provides Some POAM identifies a reporting entity’s deficiencies IS-Related Requirements for Nonreporting and risks, and explains to OIS how those Entities and Adds Legislature to State’s deficiencies and risks are being addressed and/or IS Governance Structure. Chapter 773 of mitigated. Unlike compliance certifications, which 2022 (AB 2135, Irwin) requires nonreporting are annually submitted, OIS requests quarterly entities to use FIPS 199; FIPS 200; and NIST SP updates on risk registers and POAMs. More 800-53, Revision 5 (and all of their successor information about the relevant SIMM sections publications) as sources for their IS policies, for compliance certifications and risk registers procedures, and standards. These sources and POAMs is provided in the “Major Authorities” largely are the same sources for the IS sections appendix on pages 21-23 of the report. of SAM and SIMM which contain the policies, Independent Security Assessments (ISAs) procedures, and standards that reporting entities and IS Program Audits (ISPAs) Used by OIS must follow. However, unlike reporting entities, to Oversee Reporting Entity Compliance... nonreporting entities must annually certify their In addition to the annual IS compliance compliance with legislative leadership. (We documentation, OIS uses two other primary discuss the compliance certification processes mechanisms to oversee IS compliance: ISAs and for nonreporting and reporting entities in more ISPAs. ISAs are technical analyses of an entity’s detail in the “IS Compliance” section immediately cybersecurity defenses that assess whether below.) Therefore, AB 2135 added the Legislature both networks and systems are configured to to the state’s IS governance structure specifically prevent attacks. These analyses simulate attacks for nonreporting entities. More information about to see whether networks and systems can be AB 2135 and its amendments to Government compromised and data modified and/or stolen. Code Section 11549.3 is provided in the “Major ISAs of reporting entities typically are performed Authorities” appendix on pages 21-23 of by CMD, but can be performed by third-party the report. vendors with OIS approval. ISPAs instead first review an entity’s IS policies, procedures, and IS Compliance standards, and then interview staff and test Definition of IS Compliance. In this report, networks and systems to assess whether practice we define IS compliance as the mechanisms matches IS requirements under the authorities that within the IS governance structure that are used apply to that entity. ISPAs typically are performed to oversee state entities’ implementation of IS by OIS. policies, procedures, and standards, and ensure …But Frequency of ISPAs Based on OIS’ remediation of assessment and audit findings. Determination of Reporting Entity’s Risk. We again acknowledge that there may be other ISAs are required for all reporting entities every entities involved in nonreporting entities’ IS two years (with limited exceptions). However, compliance, but we focus our IS compliance CDT cannot perform ISPAs for all reporting section on the state’s IS compliance requirements. entities due to a lack of resources. To prioritize OIS Enforces Reporting Entity IS ISPAs, OIS uses specific criteria (such as the Compliance. OIS requires all reporting entities sensitivity of the data maintained by an entity) to to submit annual IS compliance documentation. decide whether reporting entities are high risk. Two important compliance documents are (1) the Based on the criteria, OIS currently identifies IS and privacy program compliance certification, 52 reporting entities as high risk. OIS requires and (2) the risk register and plan of action and that high-risk reporting entities complete ISAs milestones (POAM). A compliance certification and ISPAs in alternating years. Reporting entities attests that a reporting entity is compliant with that are not determined by OIS to be high risk the policies, procedures, and standards in the IS can annually certify their IS practice matches sections of SAM and SIMM. A risk register and authorities in place of an ISPA (though an ISPA www.lao.ca.gov 7 AN LAO REPORT may be requested by OIS at some point). Figure 2 nonreporting entities to certify their compliance provides a visual representation of these oversight with FIPS 199; FIPS 200; and NIST SP 800-53, cycles based on OIS’ determination of reporting Revision 5 (and all of their successor publications) entities’ level of risk. annually to legislative leadership. To certify Nonreporting Entities’ IS Compliance compliance, nonreporting entities must submit Requirements Vary. Nonreporting entities largely some of the same IS compliance documentation are not subject to the state’s IS compliance to legislative leadership as reporting entities requirements under state law, except as directed submit to CDT—that is, the IS and privacy program under AB 2135 and discussed in more detail below. compliance certification and the POAM. Unlike However, as discussed above, nonreporting entities reporting entities, however, nonreporting entities have been required in the past to submit at least do not need to submit quarterly updates on their some IS compliance documentation (such as POAMs and the information requested in the POAM technology recovery plans) to CDT. Nonreporting (an older template) is slightly less comprehensive entities also might be governed by other federal than in the current POAM used by reporting entities. entities and industry organizations that require IS/IT Infrastructure and Staffing periodic IS assessments and audits, some of which are similar to state ISAs and ISPAs. Some of the Definition of IS/IT Infrastructure and Staffing. In this report, we define IS/IT infrastructure and larger nonreporting entities also might purchase staffing as the IT processes, services, systems, cyber insurance coverage, which might require and staff that support state IS programs. We entities to undergo periodic IS assessments and focus on certain processes such as the division of audits to maintain their policies. Guidance and IT procurement responsibilities between CDT and information on cyber insurance providers and their DGS; certain services and systems such as CDT’s IS compliance requirements may be provided to statewide and shared service contracts (that is, state entities by, for example, the Department consolidated contracts for IT services managed by of General Services’ (DGS’) Office of Risk and CDT and offered to multiple state entities), Security Insurance Management (OIRM). Operations Center (SOC), and State Data Center; AB 2135 Requires Nonreporting Entities and, certain staff-related issues such as Cal-CSIC to Submit IS Compliance Documentation incident response staff, IT staff classifications, to Legislature. Assembly Bill 2135 requires and IS staff recruitment and training efforts. Figure 2 Cal-CSIC Staff Provides Statewide Incident Response. Reporting Entity IS Oversight Cycles Cal-CSIC staff support IS and IT staff at state entities (along with other entities statewide) to respond Year 1 ISA Year 1 ISA Year 2 IS t b s o u r e b c a m y c b i h t e e r r e s s e . q c S u u e ta r s i t t t e s y e i f n o n c r t i i a t d i s e e s s n i t s a s t l a s a n o n c d c e a d t n o a ta P A Cal-CSIC if there are attacks and/or High-Risk Reporting Entity Cycle threats identified by entities’ IS and Reporting Entity Cycle Year 4 C I le T v s e t l a o ff f t r h e a s t p n o e n e s d e f r r e o m m e d C i a a l t - io C n S . I C Th e h Year 2 Compliance Certification eck-In ISPA Year 3 IS A s o a t n f a d t f h f o e v n a d r t a i h e t e a s o b b t r a h e s e a e r c d h IS o a n r n e d t s h / o o e u r s r i c e n e v c s e id ri e ty n t, available to the state entity. For IS = Information Security; ISA = independent security assessment; and ISPA = information security program audit. example, Cal-CSIC might respond to a serious data breach and/or 8 LEGISLATIVE ANALYST’S OFFICE AN LAO REPORT incident with the whole of its incident response Shared IT Procurement Process team and request that additional IS and IT staff, as Responsibilities Between CDT and DGS. Public well as subject matter experts, from the affected Contract Code Sections 12100-12113 divide state entity also respond. Lower-severity data breaches IT procurement process responsibilities between and/or incidents might only require a few Cal-CSIC CDT and DGS. CDT is responsible for contracts staff, and rely more on internal entity IS and IT staff for IT goods and services related to IT projects for incident response and remediation efforts. (that is, a set of activities required to plan, CDT Operates the State SOC and State develop, and implement an IT system) as well as Data Center. CDT operates the state SOC, which telecommunications goods and services, while DGS continuously monitors and reacts to threats on the is responsible for contracts for all other IT goods and California Government Enterprise Network (CGEN), services (such as the replacement of computers, the state government’s primary enterprise network. mobile devices, and other hardware). Authority Many reporting entities connect to CGEN, which over state IT procurement policy and procedures allows CDT’s SOC to identify and respond more also is divided between CDT and DGS based on quickly to attacks and/or threats to these entities. their separate responsibilities. More information CDT’s SOC also transmits any information about on Public Contract Code Sections 12100-12113 attacks and/or threats to Cal-CSIC to determine is provided in the “Major Authorities” appendix on if, for example, education segments, other pages 21-23 of the report. government entities, and/or private companies are State Entities Hire IS and IT Staff Using responding to similar attacks and/or threats. CDT Consolidated IT Classifications Approved in also maintains the State Data Center, which hosts a 2018. In 2018, the State Personnel Board approved number of state entities’ IT infrastructure (including the consolidation of 36 IT classifications into nine some of the nonreporting entities’ applications and new classifications to be used to hire both IS and systems) and monitors it for attacks and/or threats. IT staff across state entities. Six IS and IT functional CDT Also Procures and Manages Statewide areas are used to further specify workload for these and Shared Service Contracts, Including for IS. positions, including IS engineering and system CDT also procures and manages both statewide engineering, but there are no IT classifications and shared service contracts for state entities, specific to IS. including a small number of IS-related contracts. State Engaged in Number of Efforts to Statewide contracts managed by CDT allow Recruit and Train IS Staff. Cal-CSIC and CDT— vendor-hosted subscription services—IT services in collaboration with the California Department provided and primarily supported by private of Human Resources (CalHR), the Government vendors—used by most state entities to be provided Operations Agency (GovOps), and other state to all entities at a lower cost than they might entities—have set up several programs to be able to negotiate with vendors as individual recruit and train IS staff to work in state entities. entities. One example of a statewide contract is For example, the IT Cybersecurity Non-Traditional the state’s Microsoft 365 contract. Shared service Apprenticeship Program began in September 2021 contracts managed by CDT also allow for certain to train current non-IS state staff for up to two years IT services to be provided, but typically are for a to qualify for IS staff positions. Also, the Work for smaller number of state entities using a specific California campaign launched in 2023 specifically type of service to reduce their current expenditures recruits recently laid off IS and IT workers at private on similar services. One example of a shared companies on behalf of state entities. State entities service contract is security information and event also recruit from colleges and universities and, in management software that provides a group of some cases, set up programs in collaboration with state entities with several capabilities prioritized in colleges and universities to recruit and train future Cal-Secure. IS and IT staff for state entities. Finally, CDT’s Office of Professional Development and Training Center works with the department’s OIS on centralized and subscription-based IS training. www.lao.ca.gov 9 AN LAO REPORT Nonreporting Entities’ IS/IT Infrastructure Center, and use services provided through both and Staff Varies. Generally, unlike reporting statewide and shared service contracts procured entities, nonreporting entities are not required to and managed by CDT. Other nonreporting entities, use specific IS/IT infrastructure and staff under however, maintain their own IS and IT infrastructure state law. A number of nonreporting entities choose to meet industry- or program area-specific needs to use CDT’s SOC, host at least some of their and/or to ensure their independence from entities IT applications and systems on the State Data under the direct authority of the Governor. ASSESSMENT OF NONREPORTING ENTITIES’ IS COMPLIANCE The first portion of this section lays out our for state entities. We also held meetings with the research methodology. We then discuss how Department of Finance (DOF) to discuss their nonreporting entities are defined for the purposes analysis of IS-related budget proposals from of this report and recent effects of AB 2135 on nonreporting entities. IS programs. Lastly, we provide our evaluation of Review of Nonreporting Entities’ IS nonreporting entities’ IS programs. Documentation. Our office requested IS governance and compliance documentation from nonreporting RESEARCH METHODOLOGY entities in advance of the interviews. Some examples Interviews With Nonreporting Entities’ of the documentation we requested included a list of IS Programs. Our office conducted a total of the IS assessments and audits performed over the 34 one-hour interviews, primarily with staff of last five years; all of their IS policies, procedures, and nonreporting entities’ IS programs. We asked a standards; and recent IS and IT budgets with position standardized set of interview questions about IS information. We reviewed this documentation to governance, IS compliance, and IS/IT infrastructure inform our questions during the interviews and our and staffing to code nonreporting entities’ analysis in this report. Any confidential information responses. Out of the 22 entities we identified as that was contained in this documentation was nonreporting entities (which we provide later in maintained in a manner consistent with the relevant the report), our office interviewed 17 nonreporting Government Code sections and SRL requirement entities. We did not interview some of the remaining described in the “Introduction” section. five entities primarily because these were entities Review of Federal and State IS Authorities where their IT infrastructure is hosted by other and Literature. We reviewed federal and state IS entities (some of which we interviewed) or they have policies, procedures, and standards, including those no IT infrastructure. A few entities, however, did not in the “Major Authorities” appendix. We also reviewed respond to our requests for an interview. We also available literature on specific topics related to the scheduled an additional 12 interviews with reporting report, such as specific compliance requirements in entities and entities outside of the executive branch. certain critical infrastructure sectors. Meetings With Entities in State’s IS Identification of Nonreporting Entities Governance Structure. Our office also held several meetings with Cal-CSIC, OIS, and CMD. One Statutory Interpretation Used in Report to We discussed a number of topics including possible Create Nonreporting Entities List… In consultation with CDT, we created a list of nonreporting entities definitions for nonreporting entities (including the one based on one possible interpretation of state statute. used for the nonreporting entities list in this report), First, we identified entities based on the broad their understanding of nonreporting entities’ IS definition of state agency in Government Code governance and compliance activities, and their Section 11000. (There are narrower definitions in IS/IT infrastructure and staff training offerings 10 LEGISLATIVE ANALYST’S OFFICE AN LAO REPORT other code provisions.) Then, we identified which of In contrast, CDT identified some of the entities on the those entities are not under the direct authority of list as “voluntarily complying” with state IS policies, the Governor and, therefore, would not be defined procedures, and standards. We kept these entities as state entities under Government Code Section on the list because of potential noncompliance in 11546.1(e)(2). Our determination as to the reporting the future. We acknowledge alternative approaches relationship with the Governor required, for example, would result in differences with our list. As we a review of the constitutional and statutory authorities describe below, we recommend the Legislature governing these entities. This list is provided below in amend statute to clarify both the definitions and use Figure 3 as the list of nonreporting entities requested of state agency and state entity in order to clarify in the SRL. The publication of this list conforms with CDT’s IS authority. legal and policy guidance from CDT. …But Other Statutory Interpretations Could IMPACTS OF AB 2135 Change List of Nonreporting Entities. The list of ON IS PROGRAMS nonreporting entities in this report is based on one AB 2135 Requires Nonreporting Entities to statutory interpretation used to identify entities that Follow Federal IS Authorities and Undergo are not under the direct authority of the Governor ISAs Much Like Reporting Entities. Assembly and, therefore, generally are considered to be Bill 2135 requires nonreporting entities to use outside of CDT’s IS authority. This list is not definitive certain FIPS and NIST SP 800-53, Revision 5 (and or exhaustive. For example, we removed those all of their successor publications) as sources entities for which we could not determine the exact for their IS policies, procedures, and standards. reporting relationship with the Governor (such as These sources largely are the same sources for the independent entities in statute that are organized IS sections of SAM and SIMM which contain the under state agencies identified in Government Code policies, procedures, and standards that reporting Section 11546.1[e][1] in order to focus solely on those entities must follow. Assembly Bill 2135 also requires nonreporting entities clearly covered by the SRL. nonreporting entities to certify compliance with their IS policies, procedures, and standards to Figure 3 legislative leadership annually. To certify compliance, nonreporting entities must submit some of the Nonreporting Entities Based on One same IS compliance documentation to legislative Statutory Interpretation leadership as reporting entities submit to CDT— Board of Equalization that is, the IS and privacy program compliance Citizens Compensation Commission certification and the POAM. Commission on Peace Officer Standards and Training AB 2135 Addresses Some Governance and Commission on State Mandates Department of Education (Superintendent of Public Instruction) Compliance Issues That SRL Asked Us to Department of Insurance (Insurance Commissioner) Consider. The SRL asked our office to consider Department of Justice (Attorney General) whether some of the nonreporting entities could Education Audit Appeals Panel benefit from compliance with and reporting on IS Gambling Control Commission Health Benefit Exchange (Covered California) policies and procedures similar to those set by CDT, Little Hoover Commission and to provide options for the Legislature to consider Office of Tax Appeals to improve nonreporting entities’ compliance to Office of the Inspector General be comparable with reporting entities and achieve Office of the Lieutenant Governor Privacy Protection Agency a certain IS maturity level. (An entity’s IS maturity Public Utilities Commission level is how prepared state entities’ IS programs are Secretary of State to prevent and/or respond to a cyberattack State Auditor and/or threat.) We find that some of the governance State Controller State Lottery and compliance issues raised in the SRL are State Treasurer addressed by AB 2135. For example, federal IS Summer School for the Arts authorities that nonreporting entities must follow www.lao.ca.gov 11 AN LAO REPORT under AB 2135 are similar to those set by CDT, Remainder of Assessment and Options and the reporting on their compliance with those Consider Other Issues Affecting Nonreporting authorities to legislative leadership is similar to Entities’ Compliance and Maturity. Therefore, in what is required by CDT (with the exception of light of AB 2135, the remainder of our assessment annual POAM updates to the Legislature instead focuses on the results of our research on of quarterly updates required by CDT for reporting nonreporting entities’ IS programs across the topics entities). Also, the biennial ISAs required by AB 2135 of IS compliance, IS governance, and for nonreporting entities are completed by CMD IS/IT infrastructure and staffing. Similarly, the or third-party vendors in much the same way as options we provide in our report focus on issues for reporting entities, thereby helping nonreporting and needs identified in our research that have not entities to improve their IS compliance and increase already been addressed in AB 2135, but could their IS maturity level. Figure 4 shows how specific improve nonreporting entities’ IS compliance IS compliance requirements for nonreporting and maturity. and reporting entities compare after enactment of AB 2135. EVALUATION OF NONREPORTING Assembly Bill 2135, when fully implemented, ENTITIES’ IS PROGRAMS likely will provide increased oversight of To protect the confidentiality of the information nonreporting entities that, while not required by received from nonreporting entities through our state law to follow IS requirements set by OIS, documentation review and interviews, we use are state government entities largely funded with descriptive language to summarize our review appropriations approved by the Legislature. We and their responses rather than naming entities find it is important, therefore, that these entities and providing the number of responses from be subject to some of the same accountability nonreporting entities that apply to each finding. for and governance of their IS programs as reporting entities. Figure 4 Comparison of Entities’ Specific IS Compliance Requirements After Enactment of AB 2135a IS Compliance Requirement Reporting Entities Nonreporting Entitiesb Primary Governing Statutory SAM and SIMM sections 5300 (largely using FIPS 199, FIPS 200, and NIST SP 800-53. Authoritiesc FIPS and NIST SP 800-53 as the sources for Nonreporting entities also may choose to their policies, procedures, and standards). voluntarily adopt reporting entities’ primary governing statutory authorities. Assessments and Audits Biennial ISAs by CMD, and biennial ISPAs for Biennial ISAs and as-needed ISPAs from high-risk reporting entities. ISAs also can be CDT. ISAs may be completed by CMD or a completed by a third-party vendor, if approved third-party vendor. by CDT. Compliance Certification and Submission of annual compliance certifications Submission of annual compliance certifications Reporting and other IS compliance documentation (such and POAMs to legislative leadership. as POAMs) to CDT. POAMs must be updated quarterly. a Chapter 773 of 2022 (AB 2135, Irwin). b Nonreporting entities subject to these requirements might depend on which statutory interpretation is used for the definitions of “state agency” and “state entity” in CDT’s IS authority. c For more information on the governing statutory authorities we reference in this figure, please refer to the “Major Authorities” appendix at the end of the report. IS = information security; SAM = State Administrative Manual; SIMM = Statewide Information Management Manual; FIPS = Federal Information Processing Standards; NIST = National Institute for Standards and Technology; SP = Special Publication; ISAs = independent security assessments; CMD = California Military Department; ISPAs = information security program audits; CDT = California Department of Technology; and POAM = plan of action and milestones. 12 LEGISLATIVE ANALYST’S OFFICE AN LAO REPORT IS Governance This figure shows that while some nonreporting entities receive hundreds of millions of dollars Significant Differences in Nonreporting and employ thousands of staff, others receive Entity Functions, Roles, and Size. The term millions of dollars or less and employ few (if any) nonreporting entity might be useful when staff. Furthermore, the roles of some entities (for considering whether or not an entity is considered example, some of the constitutional officers) are to be outside of CDT’s IS authority but the term critical to the performance of certain state functions does not identify the relative risk for these entities. (for example, accounting and cash management) Moreover, in light of AB 2135, the term is less whereas other entities, while serving important helpful when considering if there are benefits from oversight functions, do not perform central state additional compliance and reporting requirements functions and roles. Therefore, the findings and or other resources to improve such an entity’s IS options in this report generally cannot be applied compliance and maturity. There are significant across all nonreporting entities. In many cases, differences, for example, in the types of programs our findings and options are specific to a subset and services each nonreporting entity provides, in of nonreporting entities based on their functions, the roles they serve on behalf of the state, and in roles, and size. the size of their budgets and staff. To illustrate these differences in terms of the latter, Figure 5 provides Majority of Nonreporting Entities Cited State the total fund budgets and number of positions IS Policies, Procedures, and Standards as approved for these entities in the 2022-23 Budget Primary Framework for IS Programs. A majority Act, sorted from largest to smallest budgets. of the nonreporting entities we interviewed either provided documentation showing, or confirmed in their responses, that SAM Figure 5 and SIMM Sections 5300 as well as NIST SP 800-53 are the Budgets and Positions at Nonreporting Entities in principal authorities for their own 2022-23 Budget Act IS policies, procedures, and Total Funds standards. If these were not their Nonreporting Entities (in Thousands) Positions principal authorities because, Public Utilities Commission $1,889,094 1,501 for example, they adopted other Department of Justice (Attorney General) 1,166,144 5,791 federal or industry IS authorities State Lottery 1,110,199 1,080 Health Benefit Exchange (Covered California) 759,469 1,465 as their primary framework, some State Controller 361,530 1,591 entities still cross-referenced Department of Insurance (Insurance Commissioner) 325,698 1,400 the policies, procedures, and Gambling Control Commission 154,717 40 Secretary of State 152,396 592 standards they adopted with Department of Education (Superintendent of Public 110,267 2,566 SAM and SIMM Sections 5300 Instruction) and/or NIST SP 800-53. Some Commission on Peace Officer Standards and 110,166 263 nonreporting entities were required Training Commission on State Mandates 71,876 17 to adopt other authorities specific State Auditor 46,752 217 to their programs and services State Treasurer 46,360 252 that, in many cases, were more Office of the Inspector General 42,275 214 Board of Equalization 32,563 194 prescriptive than state authorities. Office of Tax Appeals 27,138 117 Many nonreporting entities also Privacy Protection Agency 10,000 34 cited Cal-Secure as guiding their Summer School for the Arts 4,273 4 cybersecurity initiatives and Office of the Lieutenant Governor 2,708 15 Little Hoover Commission 1,292 7 technical capability investments. Education Audit Appeals Panel 1,177 5 Altogether, these findings indicate Citizens Compensation Commission 10 — nonreporting entities’ significant adoption and awareness of state IS policies, procedures, and standards. www.lao.ca.gov 13 AN LAO REPORT Many Nonreporting Entities Receive and and standards to be too expensive and/or too Use Threat Intelligence Information From limited given their constrained IS budgets. In sum, Cal-CSIC… Many of the nonreporting entities while a majority of nonreporting entities adopt we interviewed mentioned that they receive and and/or are aware of state IS policies, procedures, use threat intelligence information from Cal-CSIC and standards, many of these entities struggle to, for example, block malicious Internet Protocol to implement them based on current supporting addresses—that is, unique identifiers associated materials from CDT. with internet or network devices engaged in Some Entities Said Statutory Ambiguity hacking attempts or spamming activities— Impacted IS Program Decision-Making. Some and monitor their networks for known threat entities we interviewed were not able to provide actors—that is, organizations or people known to definitive answers to our questions about their engage in cyberattacks. Therefore, even though reporting relationship with the Governor and, nonreporting entities are not governed by the thus, were unsure if they were nonreporting state’s IS governance system, many of them are entities. Some of them had communicated with taking advantage of resources from the state’s IS Cal-CSIC and CDT to clarify whether or not they governance entities. are nonreporting entities, but a number of them …But Only Some Sought Cal-CSIC and CDT’s told us they were unable to resolve this uncertainty. Guidance on Cal-Secure Implementation. Some said the ambiguity in statute about their Although many nonreporting entities cited status made their decisions on IS governance and, Cal-Secure as one of the frameworks guiding their by extension, compliance more difficult. We find cybersecurity initiatives and technical capability the inability of some entities to determine whether implementations, only some of them said in their or not they are nonreporting entities because of the interviews that they actively sought guidance from ambiguities in CDT’s IS authority to be problematic Cal-CSIC and CDT on Cal-Secure. Some of the as it leaves oversight of these entities in limbo. entities may not have included their consultation Furthermore, it could affect the implementation with Cal-CSIC and CDT in their responses to us, of AB 2135, limiting the accountability for but to some degree, nonreporting entities may be and governance of state government entities using Cal-Secure without much guidance from largely funded with appropriations approved by Cal-CSIC and CDT to inform their implementation of the Legislature. the roadmap. IS Compliance Many Nonreporting Entities Found CDT’s Nearly All Nonreporting Entities Underwent IS Resources Difficult to Use. A majority of an ISA in the Past Several Years. According to the nonreporting entities that use SAM and our documentation review, and verified by entities’ SIMM Sections 5300 and/or NIST SP 800-53 as responses to our interview questions, we found principal authorities for their IS programs said that nearly all nonreporting entities underwent they found implementation of the framework to an ISA in the past two to three years. Some of be difficult because guidance, information, and the nonreporting entities did wait several years templates made available by CDT were hard to between ISAs, citing difficulty obtaining funding understand and not necessarily relevant to their for an ISA every two years. However, for larger program areas. We understand from CDT that nonreporting entities, biennial ISAs were only one some of the guidance, information, and templates of several IS assessments and audits undertaken, are intentionally general to allow a wider range of some of which were required by federal authorities, state entities to use them, but some nonreporting industry organizations, and some cyber insurance entities considered the lack of specificity in CDT’s providers. A number of nonreporting entities documentation to be problematic. A number cited AB 2135, as of 2022, as a reason for their of nonreporting entities also found CDT’s decision to undergo an ISA. Consistent with recommendations on hardware, software, and/or CDT’s requirement that reporting entities undergo tools to implement state IS policies, procedures, 14 LEGISLATIVE ANALYST’S OFFICE AN LAO REPORT ISAs once every two years (with some limited Some Nonreporting Entities Required to exceptions), nonreporting entities appear to be Perform Additional IS Compliance Activities by undergoing ISAs at a comparable rate consistent Cyber Insurance Providers. Some nonreporting with the intent of AB 2135. entities we interviewed said several of their IS Some Nonreporting Entities Voluntarily compliance activities were required by their cyber Comply With State IS Policies, Procedures, insurance providers to maintain their policies, and Standards. As mentioned earlier, some including certain IS assessments and audits like nonreporting entities voluntarily choose to ISAs. A small number mentioned they had to adopt comply with state IS policies, procedures, and certain IS policies, procedures, and standards as standards. Voluntary compliance means these well, and certify their compliance with particular entities undergo ISAs and ISPAs (if deemed high requirements that were set by their cyber insurance risk) and submit IS compliance documentation to providers. While cyber insurance providers are not OIS just as reporting entities do. However, unlike a formal part of the state’s IS governance structure, reporting entities, nonreporting entities can choose it appears that, at least for some nonreporting to stop their compliance with state IS policies, entities, cyber insurance providers play a key procedures, and standards at any time. None of role in their decisions to engage in certain IS the nonreporting entities we interviewed indicated compliance activities. they would stop their voluntary compliance. Some Some Nonreporting Entities Identified did mention, however, that they decided internally the Lack of Certification and Education to fully adopt some state policies and standards Opportunities for Existing Staff to Improve but modify others because, for example, their Compliance. Some nonreporting entities were alternative approach to implementation was unaware of how to achieve compliance with state IS not explicitly allowed or their budgets could not policies, procedures, and standards, and requested cover full implementation of a state policy or that CDT provide certification and education standard. Therefore, voluntary compliance shows opportunities to help existing IS and IT staff learn nonreporting entities’ willingness to follow state IS how to improve their compliance efforts and train policies, procedures, and standards, but does not others. A small number of entities sought external guarantee full compliance. training on some authorities that inform the state’s Some Nonreporting Entities in Voluntary framework (for example, NIST SP 800-53) to Compliance Cited a Lack of Documentation help them with state IS compliance activities, but Review by CDT. A small number of nonreporting said external training was not always tailored to entities that are in voluntary compliance with state state IS policies, procedures, and standards. We IS policies, procedures, and standards submitted identify other staff training-related findings from IS compliance documentation with CDT, but our research under the “IS/IT Infrastructure and received little to no feedback on their submissions. Staffing” topic in the next section, but found the These entities said the lack of response from CDT request for official certification of compliance made it difficult to, for example, determine whether knowledge from CDT to be noteworthy. deficiencies identified in ISAs had been addressed IS/IT Infrastructure and Staffing consistent with state authorities and guidance. Several Nonreporting Entities Use CDT As a result, some of these entities might not be IS and IT Service Offerings... According to able to verify that their IS compliance and maturity CDT, several nonreporting entities use some is improving due to a lack of responsiveness from combination of the department’s SOC and State CDT. If some nonreporting entities decide in the Data Center IT services. Some entities connect future to consider voluntary compliance with state to CGEN, for example, and/or host specific IS requirements, this lack of response also might applications and/or systems on the State Data discourage them from agreeing to continue with Center. Other nonreporting entities decided on voluntary compliance. more novel approaches to working with CDT’s SOC. www.lao.ca.gov 15 AN LAO REPORT For example, at least one nonreporting entity IS compliance and maturity, but also repeatedly directed a portion of its network traffic to the mentioned a lack of qualified IS staff as one department’s SOC, while maintaining their own of the barriers to further improvement of their separate entity SOC for internal network traffic. IS programs. We understand from CDT that nonreporting Several nonreporting entities also mentioned entities’ use of its SOC and State Data Center gives lower wages for state IS staff relative to the private the department more visibility into nonreporting sector, and some entities described the current entities’ IS activities and, consequently, allows CDT IT staff classifications as too broad (even with the to help these entities improve their IS compliance more specific functional areas like IS engineering) and maturity. to attract staff with the proper qualifications and …But Some Nonreporting Entities Said work experience. CalHR’s 2021 California State Private Vendors Offered Better Levels of Employee Total Compensation Report shows Service and Pricing for IS and IT Services. average turnover and vacancy rates for entry-level While some nonreporting entities cited an interest IT specialist staff are comparable to rates for in CDT’s SOC and State Data Center IT service other state staff. However, wages for entry-level offerings, these entities decided that their contracts IT specialist staff are at least 20 percent lower with private vendors offered comparable or better relative to the private sector in March 2021. Total levels of service and pricing. While we were not compensation, including health care and retirement able to compare service contracts and rates in our benefits, appears to be more comparable between research, it seems at least possible based on our private sector companies and state government, assessment of certain budget proposals related however. Consequently, whether recruiting and to the State Data Center that rates for some IT retaining IS professionals is more challenging than services offered by CDT are not competitive with other state positions (at least for entry-level IT private vendor rates. specialist staff) is somewhat unclear. However, since Nearly All Nonreporting Entities Cited March 2021, when these data were collected and Significant Challenges Hiring, Training, and published, the state’s labor market has improved Retaining IS Staff. In nearly every one of our dramatically, making it more difficult to attract interviews with nonreporting entities, entities and retain qualified IS staff. Nationally, businesses expressed difficulty recruiting, training, and and governments today are only able to fill about retaining IS staff. Several entities described their half of the needed technology job openings, efforts to improve staff recruitment, training, and whereas they could regularly fill most positions retention, but these efforts achieved mixed results. prior to the pandemic. At the same time, the state’s Some examples of these efforts included the unemployment rate has decreased from 8.4 percent aforementioned IT Cybersecurity Non-Traditional to 4.3 percent (as of February 2023). Moreover, Apprenticeship Program, similar internal entity inflation has increased at rates notably higher than apprenticeships to retrain existing staff into IS staff, recent state salary adjustments. Of the issues college outreach to create pipelines from IS-related identified across the three topics in this report, we degree programs into nonreporting entity IS offices, find that IS staff-related issues might be some of the and internship and student assistant programs. most important to address if nonreporting entities (and state entities in general) are to improve their IS Many nonreporting entities used cybersecurity compliance and maturity. training software offerings to conduct at least annual cybersecurity awareness training and Smaller Nonreporting Entities Raised perform mock phishing exercises—that is, e-mails Concerns About Procurement Delays. Some of or messages sent by internal IS staff to attempt to the smaller nonreporting entities we interviewed mislead an entity’s employees into, for example, raised issues with the division of IT procurement clicking a link or downloading a file that contains responsibilities between CDT and DGS pursuant to malware. Nonreporting entities cited the success Public Contract Code Sections 12100-12113. This of these efforts as one reason for their increased includes procurement of IT goods and services 16 LEGISLATIVE ANALYST’S OFFICE AN LAO REPORT that are needed to remediate deficiencies and entities said they did not have enough staff to weaknesses identified through, for example, ISAs dedicate to procurements for IT goods and and ISPAs. These entities cited DGS’s lack of services, which can take months or in some IT expertise as one barrier to more expeditious cases years, and instead sought improvements to procurement of IT goods and services, as streamline IT procurement processes (particularly well as unnecessarily low dollar thresholds for smaller purchases). for routine purchases. A small number of these OPTIONS TO IMPROVE NONREPORTING ENTITIES’ IS COMPLIANCE AND MATURITY Consistent with the requirements of the SRL, we 11549-11549.4 (OIS) and other statutes that provide options for legislative consideration in this cross-reference CDT’s IS authority. In addition, the section that could improve nonreporting entities’ IS Legislature could consider whether to direct CDT to compliance to be at least comparable to reporting provide accompanying legal and policy guidance to entities and to achieve a certain IS maturity level. any state entity affected by the statutory changes to We present these options to the Legislature based confirm whether or not they are now subject to the on our assessment of their benefit to nonreporting state’s IS governance structure. We emphasize this entities’ IS compliance, in order from highest to option as one potential solution to the question of lowest emphasis and impact. However, as we whether or not an entity is reporting or nonreporting discussed in our assessment, there are significant and to any statutory interpretations that lead to differences in the types of programs and services inconsistencies in the implementation of the state’s each of the nonreporting entities provide, the roles cybersecurity efforts and strategy. they serve on behalf of the state, and the size of Recommend Monitoring Nonreporting their budgets and staff. Therefore, while we do Entities’ Compliance With and Implementation generally emphasize options that could benefit all of AB 2135. We recommend monitoring nonreporting entities, we also offer options that nonreporting entities’ compliance with and might benefit only some subset of nonreporting implementation of AB 2135. Assembly Bill 2135 entities. As with our assessment, we organize added the Legislature to the state’s IS governance our options across the topics of IS governance, structure. How legislative leadership (and IS compliance, and IS/IT infrastructure and staffing. any other Members and legislative staff) use the IS compliance documentation submitted IS Governance by nonreporting entities to assess whether Consider Amending CDT’s IS Authority to nonreporting entities are indeed in compliance Address Statutory Ambiguity of State Agency could be critical to the longer-term success of and State Entity Definitions and Use. One the law. For example, implementation of AB 2135 option for legislative consideration to improve IS may require analysis of the IS compliance governance of nonreporting entities is to amend documentation to determine whether nonreporting CDT’s IS authority to address the current ambiguity entities are making progress in remediating some in the definitions and use of state agency and state of their identified deficiencies and weaknesses. entity, and make clear whether state entities are This analysis, depending on how it is performed, nonreporting or reporting. Amendments to this could require additional legislative resources authority would include changes to the relevant and expertise or further clarification of the paragraphs in Government Code Section 11546.1, responsibilities of legislative leadership (and others) but also to other sections of the department’s in statute. authority such as Government Code Sections www.lao.ca.gov 17 AN LAO REPORT Consider Directing CDT to Improve Ease of provisional budget bill language for nonreporting Use of IS-Related Guidance, Information, and entities’ IS-related budget requests to condition Templates. One other option for the Legislature the expenditure of funding on compliance with to consider to improve IS governance is to certain IS policies, procedures, and standards. direct CDT to make their IS-related guidance, For example, nonreporting entities are requesting information, and templates both simpler and more funding to implement some of the cybersecurity specific to different program areas. Materials initiatives and technical capabilities in Cal-Secure. that are difficult to understand and use could The administration could evaluate whether be one potential barrier to more adoption of and demonstrated progress towards implementation of compliance with state IS policies, procedures, and these capabilities and initiatives as a requirement standards by nonreporting entities. For example, to receive some amount of additional funding might materials could provide clearer guidance on how benefit statewide efforts to improve IS compliance to prioritize existing funding, staff, and time if new and maturity. requirements are implemented without additional The Legislature also might consider whether funding or positions. Also, CDT could consider its monitoring of AB 2135 compliance and providing guidance to state entities on how long it implementation could be used to inform its analysis will take to hear back from them on their reviews of budget requests. For example, if deficiencies or of compliance documents and, if state entities weaknesses are identified in nonreporting entities’ have not heard back, provide the relevant contact POAMs, the Legislature might condition funding information to address the issue. This guidance on their remediation and request more frequent would help, for example, nonreporting entities in updates on their POAMs. The coordination of this voluntary compliance with state requirements better analysis by the Legislature across different program understand the documentation review process. areas during the budget process also might warrant Furthermore, CDT could consider providing more consideration of internal organizational changes varied recommendations on hardware, software, to facilitate broader IS discussions (for example, and tools with different levels of service and prices the creation of a new budget subcommittee to accommodate the wide range of nonreporting focused on these and other capital outlay and IT entity budgets. issues). We emphasize these options as important Consider Directing Cal-CSIC to Increase opportunities for the administration and the Outreach to Nonreporting Entities Implementing Legislature to obtain additional information through Cal-Secure. Another option for the Legislature the budget process about nonreporting entities’ IS to consider is to direct Cal-CSIC to increase its compliance and to guide the development of their outreach to nonreporting entities known to be IS programs. implementing Cal-Secure to actively offer guidance Consider Directing Cal-CSIC and CDT on the implementation. Cal-CSIC could work with to Report to the Legislature on Cal-Secure CDT and DOF to identify nonreporting entities that Implementation. Another option the Legislature are requesting funding and positions to implement could consider, consistent with a recent Cal-Secure, and coordinate meetings and/or recommendation of our office on IS proposals workshops for these entities to ask Cal-CSIC in the Governor’s 2023-24 budget, is to direct questions about the cybersecurity initiatives and Cal-CSIC (in consultation with its partners) to report technical capabilities in the roadmap. annually to the Legislature on the implementation of Cal-Secure initiatives and technical capabilities. IS Compliance This option could improve the Legislature’s Consider Opportunities to Condition State oversight of Cal-Secure implementation, including Funding on Compliance With Federal and State nonreporting entities’ efforts using funding and/or IS Policies, Procedures, and Standards. One positions approved through the budget process. option the Legislature could consider is to request that Cal-CSIC, CDT, and DOF evaluate the use of 18 LEGISLATIVE ANALYST’S OFFICE AN LAO REPORT Consider Requiring CDT to Develop (Government Code Section 11546.45(a)(4) requires Centralized IS Training Hub for IS Compliance CDT to implement a plan to establish centralized Certification and Education. The Legislature contracts for at least some shared services, also might consider requiring CDT to develop a including IS services.) The Legislature also could centralized IS certification and training hub that consider amending current reporting requirements helps educate and certify all state entity IS staff in statute to require that CDT identify any shared on current and forthcoming state IS policies, services assessed, procured, and advertised to procedures, and standards. This centralized IS state entities in its annual report. Shared IS service training hub could build on current IS training contracts available to state entities at a lower cost programs led by CDT’s Office of Professional may incentivize additional nonreporting entities to Development and Training Center, but also focus use these services, which could provide CDT with on certification of compliance knowledge so that IS increased visibility into those entities’ IS programs. staff across state entities could easily demonstrate Consider Directing Administration to their understanding of federal and state IS policies, Expand on Existing Recruitment, Training, procedures, and standards. The Legislature also and Retention Efforts to Increase Size of IS might consider whether specific measurable goals Workforce. One other option the Legislature or outcomes for training efforts through this hub, could consider is to direct Cal-CSIC, CalHR, CDT, including the number of staff from nonreporting GovOps, and other relevant state agencies and entities that were trained, might help it monitor entities to consider expanding their existing efforts CDT’s progress in this area. to recruit, train, and retain IS staff. The Legislature Consider Requiring an Evaluation of Major could consider whether to direct these agencies Cyber Insurance Products to Understand and entities to evaluate the effectiveness of existing Compliance Requirements. One other option efforts based on, for example, the number of new the Legislature could consider is to request that IS staff recruited, trained, and/or retained and DGS’s OIRM, in consultation with CDT, provide an report back to the Legislature with a plan on how to evaluation of the major cyber insurance products expand and/or improve these efforts. currently available to state entities to determine The Legislature also could consider whether which products have IS compliance requirements to expand the scope of the evaluation to include that might improve the IS compliance and maturity considerations of employee compensation, IT staff of nonreporting entities. The Legislature also classifications, and other human resources-related might consider directing DGS, in consultation topics that might affect the ability of the state to with CDT and other relevant state departments recruit and retain IS staff. These employees are such as the Department of Insurance, to develop represented at the bargaining table by Service criteria to recommend cyber insurance products Employees International Union, Local 1000. to state entities that incorporate as one of the The state’s labor agreement with Local 1000 is goals improved IS compliance and maturity for scheduled to expire June 30, 2023. Without a new nonreporting entities. agreement, these employees will not receive a compensation increase in 2023-24. The Legislature IS/IT Infrastructure and Staffing likely will be asked to ratify a new labor agreement Consider Expanding Use of Shared Service with Local 1000 at some point this year. While we Contracts for IS Services. One option the will not know the content of a future agreement Legislature could consider, consistent with a with Local 1000 until it has been submitted to recent recommendation on IS proposals in the the Legislature for review, it is possible that such Governor’s 2023-24 budget, is to require CDT to an agreement could include provisions aimed at prioritize shared service contracts for IS services addressing recruitment and retention issues among as part of its IT contract consolidation efforts these staff. to reduce service costs and generate savings. www.lao.ca.gov 19 AN LAO REPORT Given the consistent responses we received confidential and/or sensitive. Given the need to from nonreporting entities about the difficulties in balance more visibility into some network traffic recruiting, training, and retaining IS staff, this option with the need to maintain the confidentiality of could have broader benefits to other state entities other traffic, the Legislature could request that that may be facing similar challenges. the evaluation be presented to relevant budget/ Consider Monitoring State Data Center Rate policy committee staff and propose next steps for Reassessment Process for IT Services. Another legislative consideration. option the Legislature could consider is to monitor Consider Directing Administration to Evaluate the progress of the rate reassessment process for Division of IT Procurement Responsibilities. the State Data Center that is currently underway Another option the Legislature could consider, to verify that IT services hosted by the State Data particularly for smaller nonreporting entities Center will be comparable both in levels of service with fewer procurement staff but consistent and price to major private vendors. Similar to the interaction with DGS for routine IT purchases, previous option, we offer this option because is to request that CDT and DGS evaluate their nonreporting entities’ hosting of applications and current division of IT procurement responsibilities systems on the State Data Center increases CDT’s and identify opportunities to streamline routine visibility into those entities’ IS programs. IT procurements. These opportunities could Consider Mandating Certain Network Traffic include the consolidation of IT goods and services Be Directed to CDT’s SOC for Monitoring. procurement authority under CDT, increases in the Another option the Legislature could consider is to dollar amount thresholds to delegate more IT goods request that CDT, in consultation with nonreporting and services purchases back to state entities, and entities, evaluate what network traffic from other administrative changes that could reduce the nonreporting entities could be directed to its SOC. amount of time to complete IT procurements. The Network traffic directed from nonreporting entities Legislature also could request that CDT and DGS to CDT’s SOC can be monitored for potential present the results of their evaluation to relevant cyberattacks and threats. However, nonreporting budget/policy committee staff and propose next entities might deem some network traffic to be steps for legislative consideration. 20 LEGISLATIVE ANALYST’S OFFICE AN LAO REPORT APPENDIX: MAJOR AUTHORITIES RELEVANT TO THE REPORT In this appendix, we provide federal and state system authorization before transferring data; and authorities that are relevant to this report. We documentation of remote access implementation acknowledge that there are other authorities from guidance, requirements, and restrictions prior federal entities and industry organizations that to authorization, respectively. The latest revision state entities (including nonreporting entities) to NIST SP 800-53 is Revision 5. As with FIPS, must follow. We focus on major authorities reporting entities follow many state IS policies, that inform our assessment and options for procedures, and standards based on NIST legislative consideration. SP 800-53, while nonreporting entities are required by AB 2135 to follow Revision 5 of NIST Federal Authorities SP 800-53 and all successor publications. Federal Information Processing Standards State Authorities (FIPS). FIPS are guidelines and requirements for federal computer systems developed by the Relevant Government Code Sections. Several National Institute for Standards and Technology sections of the Government Code are relevant to (NIST). Many state and local government entities, the definition of “state agency” and “state entity” as well as private companies, voluntarily use in the California Department of Technology (CDT) these standards to guide the development and Office of Information Security’s (OIS’) statutory implementation of their information security (IS) authority. Other sections establish the California programs. Reporting entities follow several state Cybersecurity Integration Center (Cal-CSIC) IS policies, procedures, and standards based on and require Cal-CSIC to develop a statewide FIPS, while nonreporting entities are required by cybersecurity strategy. Chapter 773 of 2022 (AB 2135, Irwin) to follow the • Section 8586.5. Government Code Section two FIPS below: 8586.5 contains the statutory authority • FIPS 199. FIPS 199 contains standards for Cal-CSIC. This section identifies the for federal agencies to use in categorizing Governor’s Office of Emergency Services as the importance of their information and its administrator and leader; names a number information systems based on their need of Cal-CSIC representatives from federal for the information or systems’ availability, law enforcement entities, Cal-CSIC partner confidentiality, and integrity if compromised. entities (that is, CDT, the California Highway • FIPS 200. FIPS 200 specifies minimum Patrol, and the California Military Department security requirements for federal information [CMD]), state education segments, and and information systems, and provides other state entities; and requires that a risk-based process for selecting the Cal-CSIC develop a statewide cybersecurity security controls that are needed to meet strategy, which is reflected in the state’s first these requirements. five-year IS roadmap—Cal-Secure. While reporting entities are subject to the state’s NIST Special Publication (SP) 800-53. NIST IS governance structure and, thus, must SP 800-53 catalogues privacy and security report to Cal-CSIC and follow Cal-Secure, controls for information systems to protect nonreporting entities largely are not subject against a variety of cyber risks and threats. Some to this structure. However, based on our examples of categories for these controls include research (which we discuss in more detail in account management, information exchange, the report), many nonreporting entities receive and remote access. Some examples of controls and use threat intelligence from Cal-CSIC and in these categories include disabling accounts use Cal-Secure to guide their cybersecurity based on certain criteria; verifying individual or initiatives and technical capability investments. www.lao.ca.gov 21 AN LAO REPORT • Section 11000. Government Code Section entities to assert their independence from 11000 provides the definition of a state agency the authority of OIS including IS policies, used across the executive branch’s agencies procedures, and standards issued by the and departments. The statute states that office under Government Code Section “‘state agency’ includes every state office, 11549.3. (Government Code Section officer, department, division, bureau, board, 11549.3 refers to “[a]ll state entities defined and commission.” Assembly Bill 2135 uses this in Section 11546.1.”) As we discuss in definition to avoid any statutory interpretations more detail in our report, we only include that could lead to inconsistencies in the nonreporting entities on our list for which application of the bill’s amendments to it is clearer based on constitutional or Government Code Section 11549.3 (that are statutory authorities that they are not “under discussed in more detail below). This definition the direct authority of the Governor.” of state agency applies to both reporting and » Definition of State Agency in OIS’ nonreporting entities across the Government Statutory Authority. Paragraph (e) Code except, for example, in OIS’ statutory (1) defines state agency as referring to a authority where different definitions of state list of specific state agencies such as the agency and state entity are used (as we Environmental Protection Agency, Health define below). and Human Services Agency, and Labor • Section 11546.1. Part of OIS’ larger authority, and Workforce Development Agency. Government Code Section 11546.1 requires Other agencies, however, are omitted each state agency and state entity to have such as the Government Operations a chief information officer and information Agency. This definition is narrower than security officer with specific roles and the Section 11000 definition above, which responsibilities. More importantly for leads to different statutory interpretations this report, paragraph (e) includes two of OIS’ authority over certain agencies subparagraphs with definitions for state and, by extension, certain entities. We do agency and state entity. These definitions not include any nonreporting entities on are cross-referenced in key sections of OIS’ our list (which we provide in the report) statutory authority. For example, Government based on their agency’s omission from Code Section 11549.3, which we describe this definition, but at least some entities in more detail below, requires state entities (based on different statutory interpretations) meeting the definition in Section 11546.1(e) could be considered nonreporting entities (2) (and not defined as state agencies if their state agency is omitted from the list in paragraph [e][1]) to comply with state and their reporting relationship with the IS policies, procedures, and standards. Governor is not clear. We provide more information about the • Section 11549.3. Government Code Section definitions below: 11549.3 is one of the sections outlining » Definition of State Entity in OIS’ Statutory OIS’ statutory authority. Section 11549.3(a) Authority. Paragraph (e)(2) defines a state identifies the responsibilities of OIS and entity as “an entity within the executive states that these are to include the creation, branch that is under the direct authority issuance, and maintenance of IS policies, of the Governor, including, but not limited procedures, and standards. Paragraph (b) of to, all departments, boards, bureaus, this section requires that reporting entities (that commissions, councils, and offices that is, those that meet the definition of state entity are not defined as ‘state agency’ pursuant in Section 11546.1[e][2]) comply with these to paragraph (1).” Different statutory and other filing requirements and incident interpretations of the phrase “under the notification protocols required by OIS. For this direct authority of the Governor” lead some report, we focus on the amendments made to 22 LEGISLATIVE ANALYST’S OFFICE AN LAO REPORT Section 11549.3 contained in paragraph (f) that State Administrative Manual (SAM) Section are specific to nonreporting entities. 5300. SAM contains statewide policies, procedures, and requirements developed and issued by, » AB 2135. Paragraph (f) was added to for example, CDT, the Department of Finance, Government Code Section 11549.3 to and DGS. Section 5300 contains the state’s IS require every state agency as defined policies, including those related to compliance in Government Code Section 11000 not reporting (Section 5330.2), IS program metrics subject to Section 11549.3(b) (that is, (Section 5305.9), and specific security controls. nonreporting entities) to implement policies, Reporting entities follow the state IS policies in SAM procedures, and standards that adhere to Section 5300. Nonreporting entities do not, unless FIPS 199 and 200, and NIST SP 800-53, they “voluntarily comply” with state IS policies, Revision 5. Also, nonreporting entities procedures, and standards (a concept we discuss in are required to perform an independent more detail in the report). security assessment (ISA) every two years Statewide Information Management Manual that assesses the policies, procedures, (SIMM) Section 5300. SIMM contains CDT’s and standards they implemented pursuant procedures as well as forms, instructions, and to this section. Nonreporting entities templates for compliance with IS and IT policies in are permitted to use state IS policies, SAM. In this report, we focus on two SIMM sections: procedures, and standards instead of SIMM 5305—the Risk Register and POAM—and federal authorities and use CMD instead SIMM 5330-B—IS and Privacy Program Compliance of, for example, third-party vendors for Certification. Reporting entities follow the state their ISAs. Finally, nonreporting entities are IS procedures as well as forms, instructions, and required to certify annually to legislative templates in SIMM Section 5300. Nonreporting leadership, by February 1, their compliance entities do not, unless they voluntarily comply with federal or state IS policies, procedures, with state IS policies, procedures, and standards. and standards, including the submission However, nonreporting entities are required by of a plan of action and milestones (POAM) AB 2135 to submit two IS compliance documents (explained in more detail below). annually (the compliance certification and POAM) Public Contract Code Sections 12100-12113. which are substantially similar in content and format Public Contract Code Sections 12100-12113 to the two SIMM sections below: delineate between the information technology • SIMM 5305. The POAM and risk register (IT) procurement process responsibilities of CDT identify areas of IS noncompliance or and the Department of General Services (DGS). weaknesses, assets that are at risk, the Paragraphs (b)-(e) in Section 12100 provide entity’s response to the risk as reflected in CDT with authority over contracts for IT goods controls or plans of action, and any barriers and services related to IT projects as well as or constraints on mitigation of the risk. Some telecommunications goods and services, while information about future budget requests paragraphs (f)-(g) provide DGS with authority over that are required to mitigate risk or remediate contracts for all other IT goods and services. The areas of noncompliance or weaknesses is remainder of the sections provide specific direction also provided. on particular procurement definitions, objectives, and policies. All reporting entities must follow IT • SIMM 5330-B. The compliance certification procurement processes as delineated in these attests that an entity is compliant with the sections of the Public Contract Code, while some policies, procedures, and standards in the nonreporting entities also follow these processes. IS sections of SAM and SIMM. This includes Other nonreporting entities have more flexibility in state entity leaders’ acknowledgment of their IT procurement processes and/or do not use risks identified through ISAs and other CDT and/or DGS for their procurements. documentation and oversight mechanisms. These certifications are due on an annual basis. www.lao.ca.gov 23 AN LAO REPORT LAO PUBLICATIONS This report was prepared by Brian Metzker, and reviewed by Mark C. Newton and Carolyn Chu. The Legislative Analyst’s Office (LAO) is a nonpartisan office that provides fiscal and policy information and advice to the Legislature. To request publications call (916) 445-4656. This report and others, as well as an e-mail subscription service, are available on the LAO’s website at www.lao.ca.gov. The LAO is located at 925 L Street, Suite 1000, Sacramento, California 95814. 24 LEGISLATIVE ANALYST’S OFFICE